vulns.co
/
GKData.io MCP

World Wide Web Consortium · 1 min read

Permissions Policy: inherited browser-feature authority across embedded documents

Defines browser-feature availability through inherited restrictions, document declarations and frame delegation. Feature defaults govern undeclared cases; a child cannot restore authority disabled by its parent.

Open the reference Technical StandardReviewed 2026-10-03

How to use this reference

Editorial guidance: document which component owns each capability decision and distinguish intended delegation from effective restrictions. Keep browser-feature controls separate from application authorization and user consent in integration reviews.

Before reading

  • Browser origins, embedded documents and HTTP response headers

Context and limits

  • Work in progress, not a final Recommendation or deployed-compatibility guarantee. Listed authors are the draft's editors.
  • User agents need not support every feature. Frame-level observable policy omits child response policy and later navigation, so it does not establish the loaded document's effective access.
  • Complements iframe sandboxing; it is not a complete isolation model.

Sources and provenance

  1. Permissions Policy World Wide Web Consortium · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software